Cybersecurity Threat Research βWeeklyβ Recap. This week covered multiple supply-chain intrusions and downstream impacts, including PyPI and npm compromises, along with continued targeting of GitHub Actions and cloud/dev tooling for credential theft and CI/CD propagation. Activity also ranged from extortion and ransomware tradecraft to public-facing exploitation, phishing-led loader/RAT campaigns, cross-platform botnets, and agentic container/Kubernetes abuse, alongside guidance on improving backup recovery readiness and testing.
#Shai-Hulud #Miasma #Bun #RedHatCloudServices #MiniShai-Hulud #FamousChollima #UNC3753 #LunaMoth #Vect #TheGentlemen #Aspose #VerdantBamboo #UNC5221 #BRICKSTORM #AGENTPSD #PLENET #CVE-2026-0257 #YellowKey #GreenPlasma #MiniPlasma #ClickFix #CastleLoader #PureLogs #JS.MonoGlyphRAT #Havoc #NF-e #TaxShadow #XENOFISCAL #XenoRAT #C0XMO #Gafgyt #Gamaredon #GammaLoad #GammaSteel #GammaPhish #GammaWorm #OperationFlutterBridge #FlutterShell #BlueWallet #Argamal #TA4922 #BlindEagle #Handala #BRICKSTORM
Supply Chain Compromises
- PyPI compromise in the Shai-Hulud/Miasma line used startup hooks to launch a Bun-based stealer and exfiltrate developer secrets to GitHub β Shai-Hulud Descends to Hades
- Red Hat Cloud Services npm packages were backdoored with install-time credential theft and possible propagation via stolen npm access β 32 Red Hat npm packages backdoored in 72 seconds
- A smaller Mini Shai-Hulud wave hit Red Hat npm packages, targeting GitHub Actions, cloud creds, Vault, and SSH keys β Mini Shai-Hulud Campaign Hits Red Hat Cloud Services
- Compromised Packagist development code used a malicious loader to fetch encrypted payloads tied to Famous Chollima activity β Famous Chollima Targets PHP Developers
- GitHub Actions remains a high-value target as supply chain intrusions continue across projects like Nx, Trivy, KICS, and LiteLLM β The case for GitHub Actions security
Ransomware, Extortion, and Data Theft
- UNC3753 / Luna Moth ran vishing-led extortion against U.S. legal and financial firms using RMM tools and data leak pressure β Seeking Counsel
- Vect ransomware emerged with affiliate recruitment, broad cross-platform reach, and wiper-like destructive behavior β Dark Web Profile: Vect Ransomware
- The Gentlemen ransomware tradecraft centered on double extortion, GPO abuse, and encrypted exfiltration β Emulating the Gentlemen Ransomware
- An espionage campaign quietly exfiltrated a stock exchange executiveβs Outlook mailbox over months using cloud storage and an Aspose-based stealer β Stock Exchange Executive for Five Months
Cloud, Identity, and Supply-Chain Intrusions
- VerdantBamboo / UNC5221 abused firewall and appliance access to maintain persistence with BRICKSTORM, AGENTPSD, and PLENET β VerdantBamboo: Just Another BRICKSTORM in the Firewall
- An unauthenticated MCP server enabled SSRF, LFI, and AWS credential theft from exposed internal tooling β How an Unauthenticated MCP Server Led to SSRF, LFI, and AWS Credential Theft
- TeamPCP and related supply-chain activity reinforced the risk of rapidly weaponized developer and CI/CD ecosystems β Security briefing: May 2026
Exploitation of Public-Facing Systems
- PAN-OS CVE-2026-0257 is under active exploitation against GlobalProtect portal and gateway components β Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257
- Chaotic Eclipse disclosed three Windows zero-days: YellowKey, GreenPlasma, and MiniPlasma, with PoCs published quickly after Patch Tuesday β Inside the Latest Chaotic-Eclipse Releases
- An agentic threat actor automated container escape and Kubernetes secret theft via CVE-2026-39987 in marimo β Agentic threat actor hits the orchestration plane
Phishing, Loader, and RAT Campaigns
- ClickFix used typosquatted job sites, the Finger protocol, and Windows utilities to deliver CastleLoader and a Python RAT β ClickFix Is Now Hiring
- PureLogs was delivered through a fake purchase-order lure and used in-memory loading to steal browser, Discord, crypto, and app data β Phishing Campaign Deploys JavaScript-Driven PureLogs Variant
- JS.MonoGlyphRAT abused purchase orders and proposals to establish persistence and load additional payloads β From Fake Purchase Orders to Remote Access
- A Havoc stager hid behind a Brazilian NF-e lure and delayed loading the final implant until runtime β The Demon Arrives Later
- Operation TaxShadow used tax-themed phishing, DLL hijacking, and in-memory malware with WebSocket C2 β Operation TaxShadow
- Operation XENOFISCAL targeted Afghanistanβs Ministry of Finance with a persistent XenoRAT loader chain β Operation XENOFISCAL
Botnets, Worms, and Cross-Platform Malware
- C0XMO, a modular Gafgyt variant, spread across routers, Linux, and IoT with DDoS and exploitation features β Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO
- Gamaredon continued its multi-stage GammaLoad, GammaSteel, GammaPhish, and GammaWorm chains against Ukraine β GammaPhish and GammaWorm
- Follow-on analysis detailed GammaLoad persistence, registry-cached C2, and abuse of Telegram and Cloudflare infrastructure β GammaLoad
- GammaSteel added fileless PowerShell theft, USB propagation, and dead-drop recovery for covert exfiltration β GammaSteel
- Gamaredon and Turla showed operational overlap in a 2025 espionage alliance targeting Ukraine β Gamaredon x Turla
Malvertising, Mac, and Consumer Malware
- Operation FlutterBridge used Google Ads and lookalike apps to deliver the FlutterShell backdoor on macOS β Operation FlutterBridge
- A fake BlueWallet site tricked Mac users into running an AppleScript implant that stole logins, wallets, and clipboard data β Fake BlueWallet steals passwords
- Argamal hid inside trojanized hentai games and torrents to install a backdoor and later deploy a RAT β Argamal: Malware hidden in hentai games
Regional, Sector, and Actor Activity
- TA4922 expanded globally with payroll, tax, and invoicing lures while using RATs, sideloading, and cloud hosting β TA4922: Going Global
- BlindEagle continued phishing-led theft of banking and government data across Latin America and the U.S. β Dark Web Profile: BlindEagle
- Handala branding was expanded to blend cyber, physical, and influence operations against U.S. and Israeli interests β Iran Expands Handala Brand to Physical Threats
Defensive Readiness and Recovery
- Backup jobs can appear green while still failing recovery windows, making restore testing and latency governance critical β Backup operations at scale